Vendor
ThemeREX vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 63 vulnerabilities in ThemeREX: 0 in the last 7 days and 2 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-57747, was published on 2 July 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 6
- Exploited in the wild
- 0
About ThemeREX
ThemeREX is a developer of themes and plugins for the WordPress content management system.
Latest ThemeREX vulnerabilities
- CVE-2026-57747: ThemeREX Booked CSRF in WordPress pluginmediumCVSS 6.5
- CVE-2026-57746: ThemeREX Booked broken access control in WordPress pluginhighCVSS 7.1
- CVE-2025-69175: ThemeREX Line Agency Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69174: ThemeREX Etude Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69170: ThemeREX Eventicity Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69166: ThemeREX Gunslinger Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69164: ThemeREX Skyward unauthenticated local file inclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69158: ThemeREX Granola unauthenticated local file inclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69157: ThemeREX Gamic Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69144: ThemeREX Preservation unauthenticated Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69127: ThemeREX Plumbing PHP Object InjectioncriticalCVSS 9.8EPSS 0.4%
- CVE-2025-69126: ThemeREX Fortius unauthenticated local file inclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69123: ThemeREX Snow Club Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69120: ThemeREX Dazzle Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69115: ThemeREX LuxMed Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69111: ThemeREX Reisen PHP Object InjectioncriticalCVSS 9.8EPSS 0.4%
- CVE-2025-69106: ThemeREX Imba Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2026-39529: ThemeREX Group Elementra PHP object injectioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-22338: ThemeREX EcoBlue local file inclusionhighCVSS 8.1
- CVE-2026-22331: ThemeREX AutoParts local file inclusionhighCVSS 8.1
- CVE-2025-69176: ThemeREX ITactics Local File InclusionhighCVSS 8.1EPSS 0.4%
- CVE-2025-69173: ThemeREX Tipsy Local File InclusionhighCVSS 8.1
- CVE-2025-69172: ThemeREX Resurs unauthenticated local file inclusionhighCVSS 8.1
- CVE-2025-69171: ThemeREX Orpheus Local File Inclusion in WordPress themehighCVSS 8.1
- CVE-2025-69168: ThemeREX Spike Local File Inclusion in WordPress themehighCVSS 8.1EPSS 0.5%
Most severe ThemeREX vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-69122: ThemeREX SeaFood Company PHP object injectioncriticalCVSS 9.8EPSS 0.6%
- CVE-2025-69108: ThemeREX Hot Coffee PHP Object InjectioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-39529: ThemeREX Group Elementra PHP object injectioncriticalCVSS 9.8EPSS 0.5%
- CVE-2025-69127: ThemeREX Plumbing PHP Object InjectioncriticalCVSS 9.8EPSS 0.4%
- CVE-2025-69111: ThemeREX Reisen PHP Object InjectioncriticalCVSS 9.8EPSS 0.4%
- CVE-2025-60205: ThemeREX Addons PHP Object InjectioncriticalCVSS 9.8
- CVE-2025-69168: ThemeREX Spike Local File Inclusion in WordPress themehighCVSS 8.1EPSS 0.5%
- CVE-2025-69167: ThemeREX Eros Theme Local File InclusionhighCVSS 8.1EPSS 0.5%
- CVE-2025-69165: ThemeREX Choreo local file inclusion in WordPress themehighCVSS 8.1EPSS 0.5%
- CVE-2025-69163: ThemeREX WineShop Local File InclusionhighCVSS 8.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/themerex.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ThemeREX vulnerabilities", https://junglewise.ai/threats/vendors/themerex, 26 September 2026.